ZeroHour

CVE-2023-20584

CVSS 3.1
6.0 medium
EPSS
<1%p8
Published
()
Modified
Description

IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest integrity.

Vendors
amd
Products
epyc 8024pn firmware, epyc 8024p firmware, epyc 8124pn firmware, epyc 8124p firmware, epyc 8224pn firmware, epyc 8224p firmware, epyc 8324pn firmware, epyc 8324p firmware, epyc 8434pn firmware, epyc 8434p firmware, epyc 8534pn firmware, epyc 8534p firmware
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.